CVE-2026-9282

W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().


We have discovered 30,439 live websites that are affected by CVE-2026-9282.

Run a Free Instant Scan




Affected Software

Product  W3 Total Cache
Category Cache Tools
Vulnerable Domains30,439 live websites (100% of W3 Total Cache install base)
Vulnerable Versions
  • from 0 through 2.9.4
Vulnerable Versions Count110 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - Jul 11, 2026
  • Updated - Jul 14, 2026

Credits

  • snr (finder)

Website Distribution by Country

Number of websites using CVE-2026-9282
United States11,676 websites



Germany3,775 websites
GB1,228 websites
Netherlands1,154 websites
France1,112 websites
Italy1,055 websites
Sweden842 websites
Canada769 websites
Slovakia720 websites
Australia589 websites

Website Distribution by TLD

Number of websites using CVE-2026-9282
.com14,036 websites
.de2,426 websites
.org1,041 websites
.nl967 websites
.co.uk789 websites
.it788 websites
.net761 websites
.se685 websites
.com.au546 websites
.ca513 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-9282

Top websites that are affected by CVE-2026-9282. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.com United States*,***
***********.eu Cyprus*,***
*********.com United States*,***
********.com United States*,***
************.com United States*,***
*********.com United States*,***
**********.com United States*,***
**********.com United States**,***
**********.mx United States**,***
*****************.com United States**,***
See full domain list

FAQ

CVE-2026-9282 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in W3 Total Cache
A total of 30,439 websites have been identified as vulnerable to CVE-2026-9282, based on global website indexing conducted by WebTechSurvey.
The W3 Total Cache is affected by the CVE-2026-9282 vulnerability.
W3 Total Cache versions up to and including 2.9.4 are vulnerable to CVE-2026-9282.